* Quickly get a shell on a remote machine, like I'm sitting in front of it? Powershell is nice but it's remoting model is different. You can't easily manage Windows updates for example over Powershell, it just behaves differently. * I assumed there would be something like Win98 "network neighbourhood" on steroids. Give me a list of all computers in my domain, or all computers in a group, or all computers certain users are on. AD only tells you which ones are joined, you cannot browse which ones are actually running. * Some GUI where you can ping a computer, find out which user is logged in, which software is installed, and which updates are missing.
You can find nice third party tools for all of this, or spend a lot of time writing scripts, but the basics are lacking. And the offerings from MS (WSUS, SCCM, ...) are powerful, but so far would cost us more time than they save, so I'm not really happy with the Windows ecosystem...
I don't know if AD comes without audit logging, or it was just disabled in that installation, but that seems to be a pretty big no-no for a central part of your authentication infrastructure.
(Granted, it's an anecdote, but too many WTF anecdotes make me not like a thing as well).
My limited understanding is that it has better tooling and defaults, and that it's more than just an LDAP implementation, but is it really that much better if you aren't in the Microsoft ecosystem?
[0]: https://wiki.samba.org/index.php/Setting_up_Samba_as_an_Acti...
Active Directory implements LDAP, and there are serveral other LDAP implementations. Other OSes can use Active Directory as an LDAP server, sure.